CCSK · Question #168
ENISA: In Infrastructure as a Service (IaaS), who is responsible for guest systems monitoring?
The correct answer is A. Customer. In IaaS, the cloud provider supplies virtualized compute, storage, and networking, but the customer retains full control and responsibility for everything running inside the guest operating systems, including monitoring them.
Question
ENISA: In Infrastructure as a Service (IaaS), who is responsible for guest systems monitoring?
Options
- ACustomer
- BCloud Provider
- CShared responsibility
- DInternet Service Provider (ISP)
- EData Commissioner
How the community answered
(49 responses)- A76% (37)
- B12% (6)
- C4% (2)
- D2% (1)
- E6% (3)
Why each option
In IaaS, the cloud provider supplies virtualized compute, storage, and networking, but the customer retains full control and responsibility for everything running inside the guest operating systems, including monitoring them.
Under the ENISA IaaS shared responsibility model, the cloud provider is responsible for the physical infrastructure, hypervisor, and underlying networking. The customer controls the guest OS, applications, and all workloads running on top - therefore guest systems monitoring is entirely the customer's responsibility, not shared.
The Cloud Provider is responsible for monitoring the physical infrastructure and hypervisor layer, not the guest operating systems provisioned and managed by the customer.
Shared responsibility applies to certain layers in IaaS, but guest OS monitoring sits above the provider's management boundary and belongs solely to the customer.
The ISP provides network connectivity and has no role in monitoring cloud guest systems or any IaaS layer.
The Data Commissioner is a regulatory role with no operational responsibility for monitoring cloud infrastructure at any layer.
Concept tested: IaaS shared responsibility model - guest OS monitoring
Source: https://www.enisa.europa.eu/publications/cloud-computing-security-risk-assessment
Topics
Community Discussion
No community discussion yet for this question.